Computer Security: One click to many – Home
CERN reports a phishing campaign bypassing two-factor authentication via Microsoft’s device code feature, compromising over 100 accounts and targeting thousands more.
Video
Video available
The useful question is what changes for users, developers or buyers, and whether the announcement stays industry context or becomes something people can actually use.
A recent phishing attack at CERN bypassed two-factor authentication by exploiting Microsoft’s device code authentication, which grants 90-day access without repeated logins. The attack began with an email containing a link to a Word document hosted on an external domain, masquerading as legitimate correspondence. Victims who clicked the link were prompted to enter a verification code, which attackers then used to gain full account access. The compromised accounts were subsequently used to send further phishing emails to over 5,000 recipients within the organization.
The attackers leveraged the device code authentication feature, which simplifies access to Microsoft cloud services but removes the need for CERN’s two-factor authentication. Once inside a victim’s mailbox, an automated system identified additional targets and sent phishing emails with plausible subject lines, such as 'Back orders' or 'Q’2 EMEA Project'. Over 100 accounts were compromised, requiring affected users to revoke their Microsoft tokens and re-authenticate via CERN’s 2FA-protected Single Sign-On. The incident highlights the evolving tactics used by attackers to circumvent established security measures.
In response, CERN’s Computer Security Office is exploring countermeasures, including disabling device code authentication, reducing token validity periods, or limiting daily email sends. The organization emphasizes the importance of vigilance, urging staff to verify links by hovering over URLs before clicking. Suspicious destinations, such as unfamiliar or unexpected domains like 'mata-asia[.]com', should be treated with caution to prevent account compromise.
CERN advises users to exercise caution with unexpected emails, even if they appear legitimate. The organization recommends hovering over links to check their destination and avoiding clicks on unfamiliar or suspicious URLs. For further guidance, users can consult CERN’s Monthly Report on computer security incidents or contact the Computer Security team at Computer.Security@cern.ch for assistance.